- Name and address of the person responsible
The person responsible within the meaning of the General Data Protection Regulation and other national data protection laws of the member states as well as other data protection regulations is:
Klak Solutions GmbH
Luxemburger Strasse 148
HRB 44784 (District Court Wittlich)
- Name and address of the data protection officer
The data protection officer of the person responsible is:
III. General information on data processing
- Scope of processing of personal data
In principle, we only process the personal data of our users to the extent that this is necessary to provide a functional website and our content and services. The processing of personal data of our users takes place regularly only with the consent of the user. An exception applies in such cases in which it is not possible to obtain prior consent for actual reasons and the processing of the data is permitted by statutory provisions.
- Legal basis for processing personal data
Insofar as we obtain the consent of the data subject for the processing of personal data, Article 6 (1) (a) of the EU General Data Protection Regulation (GDPR) serves as the legal basis.
Article 6 (1) (b) GDPR serves as the legal basis for the processing of personal data required to fulfill a contract to which the data subject is a party. This also applies to processing operations that are necessary to carry out pre-contractual measures.
Insofar as processing of personal data is necessary to fulfill a legal obligation to which our company is subject, Article 6 (1) (c) GDPR serves as the legal basis.
In the event that vital interests of the data subject or another natural person require the processing of personal data, Article 6 Paragraph 1 lit. d GDPR serves as the legal basis.
If the processing is necessary to safeguard a legitimate interest of our company or a third party and if the interests, fundamental rights and fundamental freedoms of the person concerned do not outweigh the first interest, Article 6 Paragraph 1 Letter f GDPR serves as the legal basis for the processing.
- Data Erasure and Storage Duration
The personal data of the person concerned will be deleted or blocked as soon as the purpose of storage no longer applies. Storage can also take place if this has been provided for by the European or national legislator in EU regulations, laws or other regulations to which the person responsible is subject. The data will also be blocked or deleted if a storage period prescribed by the standards mentioned expires, unless there is a need for further storage of the data for the conclusion or fulfillment of a contract.
- Provision of the website and creation of log files
- Description and scope of data processing
Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing computer.
The following data is collected here:
(1) Information about the browser type and version used
(2) The user's operating system
(3) The user's internet service provider
(4) The IP address of the user
(5) Date and time of access
(6) Websites from which the user's system accesses our website
(7) Websites accessed by the user's system via our website
The log files contain IP addresses or other data that enable assignment to a user. This could be the case, for example, if the link to the website from which the user arrives at the website or the link to the website to which the user switches contains personal data.
- Legal basis for data processing
The legal basis for the temporary storage of the data and the log files is Article 6 (1) (f) GDPR.
- purpose of data processing
The temporary storage of the IP address by the system is necessary to enable delivery of the website to the user's computer. For this purpose, the IP address of the user must remain stored for the duration of the session.
Storage in log files takes place to ensure the functionality of the website. In addition, we use the data to optimize the website and to ensure the security of our information technology systems. An evaluation of the data for marketing purposes does not take place in this context.
Our legitimate interest in data processing in accordance with Article 6 (1) (f) GDPR also lies in these purposes.
- Duration of storage
The data will be deleted as soon as they are no longer required to achieve the purpose for which they were collected. In the case of the collection of data for the provision of the website, this is the case when the respective session has ended.
If the data is stored in log files, this is the case after seven days at the latest. Storage beyond this is possible. In this case, the IP addresses of the users are deleted or alienated so that it is no longer possible to assign the calling client.
- Possibility of objection and elimination
The collection of the data for the provision of the website and the storage of the data in log files is absolutely necessary for the operation of the website. Consequently, there is no possibility of objection on the part of the user.
- Description and scope of data processing
The following data is stored and transmitted in the cookies:
(1) Language Settings
(2) items in a shopping cart
(3) Login Information
The following data can be transmitted in this way:
(1) Entered search terms
(2) Frequency of page views
(3) Use of Website Features
- Legal basis for data processing
The legal basis for the processing of personal data using technically necessary cookies is Article 6 (1) (f) GDPR.
The legal basis for the processing of personal data using cookies for analysis purposes is Article 6(1)(a) GDPR if the user has given their consent.
- purpose of data processing
We need cookies for the following applications:
(2) Acceptance of language settings
(3) Remembering search terms
The user data collected by technically necessary cookies are not used to create user profiles.
Analysis cookies are used to improve the quality of our website and its content. Through the analysis cookies we learn how the website is used and can thus continuously optimize our offer.
Our website stores so-called "cookies" in order to offer you a comprehensive range of functions and to make the use of our website more comfortable. "Cookies" are small files that your browser stores on your device in a designated directory. These cookies can be used to determine, among other things, whether you have visited a website before. There are session cookies, which are deleted as soon as you close your browser, and temporary or permanent cookies, which are stored on your data medium for a longer period (lifetime 1 month to 10 years) or indefinitely.
We need the cookies for web analysis to improve your shopping experience, to control our marketing activities, to individualize our product offers to all customers and advertising measures. For example, we need session cookies to show you your shopping cart across multiple pages. Temporary cookies help us to recognize you when you visit our online shop again and to show you products that are suitable for you.
Our legitimate interest in the processing of personal data in accordance with Article 6 (1) (f) GDPR also lies in these purposes.
- Duration of storage, possibility of objection and removal
The transmission of Flash cookies cannot be prevented via the browser settings, but can be prevented by changing the Flash Player settings.
- web analytics
- Use of Google Analytics
(a) This website uses Google Analytics, a web analytics service provided by Google Inc. ("Google"). Google Analytics uses so-called "cookies", text files that are stored on your computer and enable an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. If IP anonymization is activated on this website, your IP address will be shortened beforehand by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be sent to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide other services related to website activity and internet usage to the website operator.
- The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data.
- You can prevent the storage of cookies by setting your browser software accordingly; we would like to point out to you however that in this case you will if applicable not be able to use all functions of this website in full. You can also prevent the data generated by the cookie and related to your use of the website (including your IP address) being sent to Google and the processing of this data by Google by using the browser plug-in available under the following link. Download and install in: http://tools.google.com/dlpage/gaoptout?hl=de .
- This website uses Google Analytics with the extension "_anonymizeIp()". As a result, IP addresses are further processed in abbreviated form, which means that they cannot be linked to individuals. If the data collected about you has a personal reference, this will be excluded immediately and the personal data will be deleted immediately.
- We use Google Analytics to analyze and regularly improve the use of our website. We can use the statistics obtained to improve our offer and make it more interesting for you as a user. For the exceptional cases in which personal data is transferred to the USA, Google has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework. The legal basis for the use of Google Analytics is Art. 6 1 S. 1 lit. f GDPR. 2
- Use of...
2.1. Google Tag Manager: The Google Tag Manager is used on this website. Google Tag Manager is a solution from Google Inc. that allows companies to manage website tags via one interface. The Google Tag Manager is a cookie-less domain that does not collect any personal data. Google Tag Manager triggers other tags that may collect data from your site. We hereby expressly point this out. The Google Tag Manager does not access this data! If a deactivation has been carried out by the user at domain or cookie level, this will remain in place for all tracking tags implemented with Google Tag Manager.
2.2 Facebook Pixels
This website uses the visitor action pixel from Facebook to measure conversion. The provider of this service is Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. According to Facebook, however, the data collected is also transferred to the USA and other third countries.
In this way, the behavior of site visitors can be tracked after they have been redirected to the provider's website by clicking on a Facebook ad. This allows the effectiveness of the Facebook ads to be evaluated for statistical and market research purposes and future advertising measures to be optimized.
The data collected is anonymous to us as the operator of this website, we cannot draw any conclusions about the identity of the user. However, the data is stored and processed by Facebook so that a connection to the respective user profile is possible and Facebook uses the data for its own advertising purposes, in accordance with the
Facebook Data Use Policy. This enables Facebook to place advertisements on Facebook pages and outside of Facebook. This use of the data cannot be influenced by us as the site operator.
The use of Facebook pixels is based on Art. 6 Para. 1 lit. f GDPR. The website operator has a legitimate interest in effective advertising measures, including social media. If a corresponding consent was requested (e.g. consent to the storage of cookies), the processing takes place exclusively on the basis of Article 6 Paragraph 1 lit. the consent can be revoked at any time.
2.3. Google Analytics Remarketing
This website uses the functions of Google Analytics Remarketing in connection with the cross-device functions of Google Ads and Google DoubleClick. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
This function makes it possible to link the advertising target groups created with Google Analytics Remarketing to the cross-device functions of Google Ads and Google DoubleClick. In this way, interest-related, personalized advertising messages that have been adapted to you depending on your previous usage and surfing behavior on one end device (e.g. mobile phone) can also be displayed on another of your end devices (e.g. tablet or PC).
If you have given your consent, Google will link your web and app browser history to your Google account for this purpose. In this way, the same personalized advertising messages can be placed on every device on which you log in with your Google account.
To support this feature, Google Analytics collects Google-authenticated user IDs, which are temporarily linked to our Google Analytics data to define and create audiences for cross-device advertising.
You can permanently opt out of cross-device remarketing/targeting by disabling personalized advertising; follow this link: https://www.google.com/settings/ads/onweb/.
The summary of the recorded data in your Google account is based solely on your consent, which you can give or revoke with Google (Article 6 (1) (a) GDPR). In the case of data collection processes that are not merged in your Google account (e.g. because you do not have a Google account or have objected to the merger), the collection of data is based on Article 6 (1) (f) GDPR. The legitimate interest results from the fact that the website operator has an interest in the anonymous analysis of website visitors for advertising purposes.
Further information and the data protection regulations can be found in Google's data protection declaration at:
This website uses the etracker analysis service. The provider is etracker GmbH, Erste Brunnenstraße 1, 20459 Hamburg, Germany. User profiles can be created from the data under a pseudonym. Cookies can be used for this. Cookies are small text files that are stored locally in the cache of your Internet browser. The cookies make it possible to recognize your browser again. The data collected with the etracker technologies will not be used to personally identify visitors to this website without the separate consent of the person concerned and will not be combined with personal data about the bearer of the pseudonym.
etracker cookies remain on your end device until you delete them.
The storage of etracker cookies and the use of this analysis tool are based on Article 6 Paragraph 1 lit. f GDPR. The website operator has a legitimate interest in the anonymous analysis of user behavior in order to optimize both its website and its advertising. If a corresponding consent was requested (e.g. consent to the storage of cookies), the processing takes place exclusively on the basis of Article 6 Paragraph 1 lit. the consent can be revoked at any time.
You can object to the collection and storage of data at any time with effect for the future. To object to data collection and storage of your visitor data for the future, click on the following button. This sets an opt-out cookie with the name "_et_oi_v2" from etracker. This ensures that no visitor data from your browser for this domain will be collected and stored by etracker in the future. Please do not delete this cookie as long as you wish to maintain your objection. Further information can be found in etracker's data protection regulations: https://www.etracker.com/datenschutz/.
2.5 TikTok Pixel
We use on this website the so-called "TikTok pixel" of the provider TikTok (for EU: TikTok Information Technologies UK Limited, Aviation House, 125 Kingsway Holborn, London, WC2B 6NH.). This is a code which we have implemented on our site. With the help of this code, in the case of your explicit consent, a connection is established with the TikTok servers when you visit our website, in order to track your behavior on our website. For example, when you purchase a product on our website, the TikTok pixel is triggered and stores your actions on our website in one or more cookies. You have the option to revoke your consent at any time with effect for the future. There are no costs for this other than the basic rates.
Personal data such as the IP address and other information such as device ID, device type and operating system may also be transferred to TikTok. TikTok uses email or other login or device information to identify users of our website and associate their actions with a TikTok user account.
TikTok uses this data to display targeted and personalized advertising to its users and to create interest-based user profiles. The collected data is anonymous and not visible to us and is only used to measure the effectiveness of ad placements.
In principle, your data will be processed within the EU or the EEA. For this purpose, a corresponding data protection agreement has been concluded with TikTok. If personal data is transferred to countries outside the EU or EEA, this is done within the framework of the Commission's model contracts for the transfer of personal data to third countries (i.e. standard contractual clauses).
https://www.tiktok.com/legal/new-privacy-policy?lang=de-DEConclusion of a contract for order processing
We have concluded an order processing contract with etracker and fully implement the strict requirements of the German data protection authorities when using etracker.
VII. Newsletter + Back in Stock + Easy Feedback
With your consent, you can subscribe to our newsletter or our back in stock program, with which we will inform you about our current interesting offers or as soon as a product is available/in stock/available again. The advertised goods and services are named in the declaration of consent.
- Double opt-in
We use the so-called double opt-in procedure to register for our newsletter. This means that after you have registered, we will send you an e-mail to the e-mail address provided, in which we ask you to confirm that you wish to receive the newsletter. If you do not confirm your registration within [24 hours], your information will be blocked and automatically deleted after one month. In addition, we store the IP addresses you use and the times of registration and confirmation. The purpose of the procedure is to be able to prove your registration and, if necessary, to be able to clarify any possible misuse of your personal data.
- Necessary information
The only mandatory information for sending the newsletter is your e-mail address. .
After your confirmation, we will save your e-mail address for the purpose of sending the newsletter. The legal basis is Article 6 Paragraph 1 Clause 1 Letter a GDPR.
- withdrawal of consent
You can revoke your consent to the sending of the newsletter at any time and unsubscribe from the newsletter. You can declare your revocation by clicking on the link provided in each newsletter e-mail or by sending a message to the contact details given in the imprint.
- Evaluation of user behavior
This website uses the services of MailChimp to send newsletters. The provider is Rocket Science Group LLC, 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA.
MailChimp is a service with which, among other things, the sending of newsletters can be organized and analyzed. If you enter data for the purpose of subscribing to the newsletter (e.g. e-mail address), this will be stored on the MailChimp servers in the USA.
MailChimp is certified according to the "EU-US Privacy Shield". The "Privacy Shield" is an agreement between the European Union (EU) and the USA, which is intended to ensure compliance with European data protection standards in the USA.
With the help of MailChimp we can analyze our newsletter campaigns. When you open an email sent with MailChimp, a file contained in the email (so-called web beacon) connects to the MailChimp servers in the USA. In this way it can be determined whether a newsletter message has been opened and which links have been clicked on. Technical information is also recorded (e.g. time of retrieval, IP address, browser type and operating system). This information cannot be assigned to the respective newsletter recipient. They are used exclusively for the statistical analysis of newsletter campaigns. The results of these analyzes can be used to better adapt future newsletters to the interests of the recipients.
If you do not want an analysis by MailChimp, you must unsubscribe from the newsletter. For this purpose, we provide a corresponding link in every newsletter message.
The data processing takes place on the basis of your consent (Art. 6 Para. 1 lit. a DSGVO). You can revoke this consent at any time by unsubscribing from the newsletter. The legality of the data processing operations that have already taken place remains unaffected by the revocation.
The data you have stored with us for the purpose of subscribing to the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and deleted from the newsletter distribution list after you have canceled the newsletter. Data stored by us for other purposes remain unaffected.
After you have been removed from the newsletter distribution list, your e-mail address may be stored in a blacklist by us or the newsletter service provider in order to prevent future mailings. The data from the blacklist is only used for this purpose and is not merged with other data. This serves both your interest and our interest in complying with the legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR). Storage in the blacklist is not limited in time. You can object to the storage if your interests outweigh our legitimate interests.
Conclusion of a data processing agreement
We have concluded a so-called "Data Processing Agreement" with MailChimp, in which we oblige MailChimp to protect our customers' data and not to pass it on to third parties.
We use Easy-Feedback for quality surveys. You can find Easy-Feedback’s data protection declaration, which is independent of us, under the following link: https://easy-feedback.de/privacy/datenschutz-teilnahme-umfragen/
Easy-Feedback is an independent brand of easyfeedback GmbH, Ernst-Abbe-Straße 4, 56070 Koblenz
VIII. Social Media Plugins
- Plug-ins used:
We currently use the following social media plug-ins: Facebook, Instagram, Twitter and LinkedIn. We use the so-called two-click solution. This means that when you visit our site, no personal data is initially passed on to the providers of the plug-ins. You can identify the provider of the plug-in by the marking on the box above its initials or the logo. We give you the opportunity to communicate directly with the provider of the plug-in via the button. Only if you click on the marked field and thereby activate it will the plug-in provider be informed that you have accessed the corresponding website of our online offer. In addition, the data mentioned under (3) of this declaration will be transmitted. According to the provider in Germany, the IP address is anonymized immediately after collection on Facebook. By activating the plug-in, your personal data is transmitted to Facebook and stored there (in the USA for US providers). Since the plug-in provider collects data in particular via cookies, we recommend that you delete all cookies via the security settings of your browser before clicking on the grayed-out box.
- No influence on processing
We have no influence on the collected data and data processing procedures, nor are we aware of the full extent of the data collection, the purposes of the processing, the storage periods. We also have no information on the deletion of the data collected by the plug-in provider.
- Plug-in Provider
The plug-in provider stores the data collected about you as usage profiles and uses them for advertising, market research and/or needs-based design of its website. Such an evaluation is carried out in particular (also for users who are not logged in) to display needs-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, whereby you must contact the respective plug-in provider to exercise this right. With the plug-in we offer you the opportunity to interact with the social network and other users, so that we can improve our offer and make it more interesting for you as a user. The legal basis for the use of the plug-ins is Article 6 Paragraph 1 Clause 1 Letter f GDPR.
- data sharing
The data is passed on regardless of whether you have an account with the plug-in provider and are logged in there. If you are logged in to the plug-in provider, your data collected from us will be assigned directly to your existing account with the plug-in provider. If you press the activated button and e.g. B. link the page, the plug-in provider also stores this information in your user account and shares it publicly with your contacts. We recommend that you log out regularly after using a social network, but especially before activating the button, as this way you can avoid being assigned to your profile with the plug-in provider.
- Further information
Further information on the purpose and scope of the data collection and its processing by the plug-in provider can be found in the data protection declaration communicated below. There you will also receive further information on your rights in this regard and setting options to protect your privacy.
- Address of the respective plug-in provider and URL with its data protection information:
- a) Facebook Inc., 1601 Willow Road, Menlo Park, California 94025, USA; http://www.facebook.com/policy.php ; Further information on data collection: http://www.facebook.com/help/186325668085084 , http://www.facebook.com/about/privacy/your-info-on-other#applications and http://www.facebook .com/about/privacy/your-info#everyoneinfo . Facebook has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework .
- b) Instagram: Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland
Facebook Ireland Limited is a company registered under the laws of Ireland.
Commercial register number: 462932; https://www.facebook.com/help/instagram/155833707900388 ; Facebook has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework .
- c) Twitter, Inc., 1355 Market St, #900, San Francisco, California 94103, USA; https://twitter.com/privacy . Twitter has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework .
- d) LinkedIn Corporation, 1000 W. Maude Ave. Sunnyvale, California 94085; http://www.linkedin.com/legal/privacy-policy . LinkedIn has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework .
- Embedding YouTube videos
- We have integrated YouTube videos into our online offer, which are stored on http://www.YouTube.com and can be played directly from our website.
- By visiting the website, YouTube receives the information that you have accessed the corresponding subpage of our website. In addition, the data mentioned under § 3 of this declaration will be transmitted. This occurs regardless of whether YouTube provides a user account through which you are logged in or whether there is no user account. If you are logged in to Google, your data will be assigned directly to your account. If you do not wish to be associated with your profile on YouTube, you must log out before activating the button. YouTube stores your data as usage profiles and uses them for advertising, market research and/or needs-based design of its website. Such an evaluation is carried out in particular (even for users who are not logged in) to provide needs-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, whereby you must contact YouTube to exercise this right.
- Further information on the purpose and scope of the data collection and its processing by YouTube can be found in the data protection declaration. There you will also find further information on your rights and setting options to protect your privacy: https://www.google.de/intl/de/policies/privacy. Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.
- Contact form, registration on the website and email contact
- Description and scope of data processing
There is a contact form on our website which can be used to contact us electronically. If a user takes advantage of this option, the data entered in the input mask will be transmitted to us and saved. These dates are:
- E-mail address
- phone number
At the time the message is sent, the following data is also stored:
List of the relevant data such as:
(1) The IP address of the user
(2) Date and time of registration
Your consent will be obtained for the processing of the data during the sending process and reference will be made to this data protection declaration.
Alternatively, you can contact us via the email address provided. In this case, the user's personal data transmitted with the e-mail will be stored.
In this context, the data will not be passed on to third parties. The data will only be used to process the conversation.
- Legal basis for data processing
The legal basis for processing the data is Article 6(1)(a) GDPR if the user has given their consent.
The legal basis for the processing of data transmitted in the course of sending an email is Article 6 Paragraph 1 Letter f GDPR. If the e-mail contact is aimed at concluding a contract, the additional legal basis for processing is Art. 6 (1) (b) GDPR.
- purpose of data processing
The processing of the personal data from the input mask serves us solely to process the contact. If contact is made by e-mail, this is also the necessary legitimate interest in the processing of the data.
The other personal data processed during the sending process serve to prevent misuse of the contact form and to ensure the security of our information technology systems.
- Duration of storage
The data will be deleted as soon as they are no longer required to achieve the purpose for which they were collected. For the personal data from the input mask of the contact form and those sent by e-mail, this is the case when the respective conversation with the user has ended. The conversation is over when it can be inferred from the circumstances that the facts in question have been finally clarified.
The additional personal data collected during the sending process will be deleted after a period of seven days at the latest.
- Possibility of objection and elimination
The user has the option to revoke his consent to the processing of personal data at any time. If the user contacts us by email, he can object to the storage of his personal data at any time. In such a case, the conversation cannot be continued.
To exercise your right to revoke your consent, a simple email to: firstname.lastname@example.org is sufficient
All personal data that was saved in the course of making contact will be deleted in this case.
- Registration on this site
In principle, you can place orders on our site without registering. However, you can register on this website to use additional functions. We only use the data entered for the purpose of using the respective offer or service for which you have registered. The mandatory information requested during registration must be provided in full. Otherwise the registration will be rejected.
For important changes, such as the scope of the offer or technically necessary changes, we use the e-mail address provided during registration to inform you in this way.
The data entered during registration is processed for the purpose of implementing the user relationship established by registration and, if necessary, initiating further contracts, Article 6 (1) (b) GDPR.
The data collected during registration will be stored by us for as long as you are registered on this website and will then be deleted. Statutory retention periods remain unaffected.
- Amazon Affiliate Program
- Klak Solutions GmbH is a participant in the Amazon Europe S. à. right l. and affiliates of the advertising program designed to provide a medium for websites to earn advertising reimbursements through the placement of advertisements and links to amazon.de. With the program, we are interested in showing you advertisements that are of interest to you and that make our website more interesting for our users.
- In order to provide the advertisements, statistical information about you is collected, which is processed by our advertising partners. By visiting the website, Amazon receives the information that you have accessed the corresponding page on our website. To do this, Amazon uses web beacons to determine your needs and may place a cookie on your computer. The data mentioned under V. of this information will be transmitted. We have no influence on the data collected, nor do we know the full extent of the data collection and the storage period. If you are logged in to Amazon, your data can be assigned directly to your account there. If you do not wish to be associated with your Amazon profile, you must log out. It is possible that your data will be passed on to Amazon contractual partners and authorities. We have no influence on the data collected, nor are we aware of the full extent of the data collection. The data is transferred to the USA and evaluated there. The legal basis for the processing of your data is Article 6 Paragraph 1 Clause 1 Letter f GDPR.
- You can prevent the installation of cookies from the Amazon partner program in various ways: a) by setting your browser software accordingly; in particular, suppressing third-party cookies means that you will not receive any ads from third-party providers; b) by deactivating interest-based ads on Amazon via the link http://www.amazon.de/gp/dra/info ; c) by deactivating the interest-based ads of the providers who are part of the self-regulatory campaign "About Ads" via the link http://www.aboutads.info/choices , whereby these settings will be deleted if you delete your cookies. We would like to point out that in this case you may not be able to use all the functions of this offer to their full extent.
XII. payment provider
On our website we offer, among other things, payment via PayPal. The provider of this payment service is PayPal (Europe) S.à.rl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter "PayPal").
If you choose to pay via PayPal, the payment details you enter will be sent to PayPal. Your data is transmitted to PayPal on the basis of Art. 6 (1) (b) GDPR.
You can read more about this in PayPal's data protection declaration under the following link: https://www.paypal.com/de/webapps/mpp/ua/privacy-full?locale.x=de_DE
On our website we offer, among other things, payment with the services of Klarna. The provider is Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden (hereinafter "Klarna").
Klarna offers various payment options (e.g. installment purchase). If you decide to pay with Klarna (Klarna checkout solution), Klarna will collect various personal data from you. You can read details about this in Klarna's data protection declaration under the following link: https://www.klarna.com/de/datenschutz/ .
Details on the use of Klarna cookies can be found in the following link:
Your data is transmitted to Klarna on the basis of Art. 6 (1) (b) GDPR.
- Instant bank transfer
On this website we offer, among other things, payment by means of "Sofortüberweisung". The provider of this payment service is Sofort GmbH, Theresienhöhe 12, 80339 Munich (hereinafter “Sofort GmbH”).
With the help of the "Sofortüberweisung" procedure, we receive a payment confirmation from Sofort GmbH in real time and can immediately start fulfilling our obligations.
If you have decided to use the "Sofortüberweisung" payment method, send the PIN and a valid TAN to Sofort GmbH, which they can use to log into your online banking account. Sofort GmbH automatically checks your account balance after logging in and carries out the transfer to us using the TAN you sent. It then immediately sends us a transaction confirmation. After logging in, your sales, the credit limit of the overdraft facility and the existence of other accounts and their balances are automatically checked.
In addition to the PIN and the TAN, the payment data you enter as well as personal data are transmitted to Sofort GmbH. Your personal data includes first and last name, address, telephone number(s), email address, IP address and any other data required for payment processing. The transmission of this data is necessary to establish your identity beyond doubt and to prevent attempts at fraud.
The transmission of your data to Sofort GmbH takes place on the basis of Art. 6 Para. 1 lit. b GDPR.
Details on payment with immediate transfer can be found in the following links: https://www.sofort.de/datenschutz.html and https://www.klarna.com/sofort/ .
- Shopify Payments
Data protection information on Stripe Payments Europe Ltd. can be found here: https://stripe.com/de/privacy
XIII. rights of the data subject
If personal data is processed by you, you are the data subject within the meaning of the GDPR and you have the following rights vis-à-vis the person responsible:
- right of providing information
You can request confirmation from the person responsible as to whether personal data relating to you is being processed by us.
If such processing is present, you can request information from the person responsible for the following information:
(1) the purposes for which the personal data are processed;
(2) the categories of personal data being processed;
(3) the recipients or categories of recipients to whom your personal data has been or will be disclosed;
(4) the planned duration of the storage of the personal data concerning you or, if specific information on this is not possible, criteria for determining the storage duration;
(5) the existence of a right to rectification or erasure of personal data concerning you, a right to restriction of processing by the person responsible or a right to object to this processing;
(6) the existence of a right of appeal to a supervisory authority;
(7) all available information about the origin of the data if the personal data are not collected from the data subject;
(8) the existence of automated decision-making including profiling in accordance with Art. 22 (1) and (4) GDPR and - at least in these cases - meaningful information about the logic involved and the scope and intended effects of such processing for the data subject.
You have the right to request information as to whether your personal data is being transmitted to a third country or to an international organization. In this context, you can request to be informed of the appropriate guarantees pursuant to Art. 46 GDPR in connection with the transmission.
- Right to Rectification
You have a right to correction and/or completion to the person responsible if the processed personal data concerning you is incorrect or incomplete. The person responsible must make the correction immediately.
- Right to restriction of processing
Under the following conditions, you can request the restriction of the processing of your personal data:
(1) if you dispute the accuracy of the personal data concerning you, for a period enabling the person responsible to verify the accuracy of the personal data;
(2) the processing is unlawful and you refuse to delete the personal data and instead request that the use of the personal data be restricted;
(3) the person responsible no longer needs the personal data for the purposes of processing, but you need them to assert, exercise or defend legal claims, or
(4) if you have lodged an objection to the processing pursuant to Art. 21 (1) GDPR and it has not yet been determined whether the legitimate reasons of the person responsible outweigh your reasons.
If the processing of personal data concerning you has been restricted, this data - apart from its storage - may only be used with your consent or to assert, exercise or defend legal claims or to protect the rights of another natural or legal person or for reasons of important public interest of the Union or a Member State are processed.
If the restriction of processing has been restricted according to the above conditions, you will be informed by the person responsible before the restriction is lifted.
- Right to Erasure
- a) Obligation to delete
You can request the person responsible to delete the personal data concerning you immediately, and the person responsible is obliged to delete this data immediately if one of the following reasons applies:
(1) The personal data concerning you are no longer necessary for the purposes for which they were collected or otherwise processed.
(2) You revoke your consent on which the processing was based pursuant to Article 6 Paragraph 1 Letter a or Article 9 Paragraph 2 Letter a GDPR and there is no other legal basis for the processing.
(3) You object to the processing in accordance with Article 21 (1) GDPR and there are no overriding legitimate reasons for the processing, or you object to the processing in accordance with Article 21 (2) GDPR.
(4) The personal data concerning you was processed unlawfully.
(5) The deletion of personal data concerning you is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the person responsible is subject.
(6) The personal data concerning you was collected in relation to information society services offered pursuant to Article 8 (1) GDPR.
- b) Information to third parties
If the person responsible has made the personal data relating to you public and is obliged to delete it in accordance with Art. 17 (1) GDPR, he shall take appropriate measures, including technical measures, to protect the person responsible for data processing, taking into account the available technology and the implementation costs , who process the personal data, that you, as the data subject, have requested them to delete all links to this personal data or copies or replications of this personal data.
- c) Exceptions
The right to erasure does not exist if processing is necessary
(1) to exercise the right to freedom of expression and information;
(2) to fulfill a legal obligation that requires processing under Union or Member State law to which the controller is subject, or to perform a task that is in the public interest or in the exercise of official authority vested in the controller became;
(3) for reasons of public interest in the field of public health in accordance with Article 9 (2) lit. h and i and Article 9 (3) GDPR;
(4) for archiving purposes in the public interest, scientific or historical research purposes or for statistical purposes pursuant to Art. 89 (1) GDPR, insofar as the law mentioned under Section a) is likely to make it impossible or seriously impair the achievement of the objectives of this processing, or
(5) to assert, exercise or defend legal claims
- right to information
If you have asserted the right to correction, deletion or restriction of processing against the person responsible, he is obliged to inform all recipients to whom the personal data concerning you have been disclosed of this correction or deletion of the data or restriction of processing, unless this proves to be impossible or involves a disproportionate effort.
You have the right to be informed about these recipients by the person responsible.
- Right to data portability
You have the right to receive the personal data concerning you that you have provided to the person responsible in a structured, common and machine-readable format. In addition, you have the right to transmit this data to another person responsible without hindrance by the person responsible for providing the personal data, provided that
(1) the processing is based on consent pursuant to Article 6(1)(a) GDPR or Article 9(2)(a) GDPR or on a contract pursuant to Article 6(1)(b) GDPR and
(2) the processing is carried out using automated procedures.
In exercising this right, you also have the right to have the personal data concerning you transmitted directly from one person responsible to another person responsible, insofar as this is technically feasible. The freedoms and rights of other people must not be impaired by this.
The right to data portability does not apply to processing of personal data that is required to perform a task that is in the public interest or in the exercise of official authority that has been assigned to the controller.
- Right to object
You have the right, for reasons arising from your particular situation, to object at any time to the processing of your personal data, which is based on Article 6 Paragraph 1 lit. e or f GDPR; this also applies to profiling based on these provisions.
The person responsible no longer processes the personal data relating to you unless he can demonstrate compelling legitimate grounds for the processing which outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
If the personal data concerning you is processed in order to operate direct advertising, you have the right to object at any time to the processing of your personal data for the purpose of such advertising; this also applies to profiling insofar as it is associated with such direct advertising.
If you object to the processing for direct marketing purposes, the personal data relating to you will no longer be processed for these purposes.
In connection with the use of information society services, you have the option – notwithstanding Directive 2002/58/EC – to exercise your right to object by means of automated procedures that use technical specifications.
- Right to revoke the declaration of consent under data protection law
You have the right to revoke your declaration of consent under data protection law at any time. The revocation of the consent does not affect the legality of the processing carried out on the basis of the consent up to the point of revocation.
- Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your place of residence, your place of work or the place of the alleged infringement, if you believe that the processing of your personal data is contrary to violates the GDPR.
The supervisory authority to which the complaint was lodged will inform the complainant about the status and the results of the complaint, including the possibility of a judicial remedy under Art. 78 GDPR.
XIV. Updating and changing this data protection declaration
This data protection declaration is currently valid and has the status of November 2021.
Due to the further development of our website and offers on it or due to changed legal or official requirements, it may become necessary to change this data protection declaration. You can call up and print out the current data protection declaration at any time on the website at www.myklak.com.